CVE-2026-85636: jofpin trape Login Endpoint stats.py missing authentication
A vulnerability was identified in jofpin trape 1.0.0. Affected by this vulnerability is an unknown functionality of the file core/stats.py of the component Login Endpoint. The manipulation leads to missing authentication. The attack may be initiated remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
The attack can be initiated remotely and requires no privileges or user interaction. Public exploit availability means exposed instances should be treated as having a practical exploitation risk.
What component should be investigated first?
The affected functionality is in core/stats.py, associated with the Login Endpoint. Review whether this endpoint is reachable remotely and whether it enforces authentication as intended.
Is a vendor fix available?
The provided information does not identify a fix. It states that the project was notified through an issue report but had not responded at the time of publication.